Key takeaways
- Most incidents come from weak access control, not exotic attacks.
- Review administrator and manager permissions regularly.
- Restrict administrative access by IP and use strong authentication.
Operating system
- Apply security updates on a schedule.
- Disable unused services and remote access methods.
- Use endpoint protection suitable for servers.
Administrator and manager accounts
- One named account per person, no shared logins.
- Least-privilege permissions for dealing, support and finance teams.
- Remove accounts immediately when staff leave.
- Rotate credentials and review access quarterly.
Network
- IP whitelisting for administrative access.
- Segmentation between trade, access and back-office systems.
- DDoS protection in front of access servers.
Backups and monitoring
- Automated backups stored off-server and tested by restore.
- Alerts for failed logins, configuration changes and unusual activity.